summaryrefslogtreecommitdiff
path: root/debian
diff options
context:
space:
mode:
authorRuss Allbery <eagle@eyrie.org>2018-04-01 14:09:03 -0700
committerRuss Allbery <eagle@eyrie.org>2018-04-01 14:09:03 -0700
commit3d1b0e4a87463fa7550b73d80de8e56bb576b54e (patch)
tree3c66ce824d95f69d49353a5bdd260a7d03e24fef /debian
parentb3764d7e6a8b64bd27d67bb35c2722ec268edb47 (diff)
Add changelog for upstream 3.14 release
Diffstat (limited to 'debian')
-rw-r--r--debian/changelog8
1 files changed, 7 insertions, 1 deletions
diff --git a/debian/changelog b/debian/changelog
index 97489b8..6e71b2b 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,5 +1,11 @@
-remctl (3.13-2) UNRELEASED; urgency=medium
+remctl (3.14-1) UNRELEASED; urgency=medium
+ * New upstream release.
+ - SECURITY: Fix use-after-free and double-free when handling the sudo
+ option in remctld. This may allow (with some difficulty) arbitrary
+ command execution on the server by streaming clients if the sudo
+ option was used in the server configuration. Thanks, Santosh
+ Ananthakrishnan. (CVE-2018-0493)
* Add upstream-vcs-tag pattern to debian/gbp.conf.
-- Russ Allbery <rra@debian.org> Sun, 01 Apr 2018 14:03:29 -0700